Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Log HijackThis plzzzzzzz


  • This topic is locked This topic is locked
6 replies to this topic

#1 germany davy

germany davy

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:56 PM

Posted 21 February 2010 - 08:12 PM

mon pc est ralenti ma connexion aussi

J'utilise Windows 7 integrale ultime, avg 9 libre Qui NE PEUT pas Mettre à jour liaison du scanneur, et j'ai le pc Qui est en perte de vitesse

Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrateur at 2010-02-21 20:14:27
Microsoft Windows 7 Édition Intégrale
System drive C: has 18 GB (35%) free of 50 GB
Total RAM: 3071 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:14:43, on 21/02/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\system32\conhost.exe
C:\Program Files\PokerStars\PokerStars.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Administrateur\Desktop\RSIT.exe
C:\Program Files\trend micro\Administrateur.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: Notes &liées OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O13 - Gopher Prefix:
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo...sreqlab_nvd.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.5.0.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup...15111/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3489645D-0B16-40EE-A68F-46447D04D258}: NameServer = 217.175.160.11,217.175.160.12
O17 - HKLM\System\CS1\Services\Tcpip\..\{3489645D-0B16-40EE-A68F-46447D04D258}: NameServer = 217.175.160.11,217.175.160.12
O17 - HKLM\System\CS2\Services\Tcpip\..\{3489645D-0B16-40EE-A68F-46447D04D258}: NameServer = 217.175.160.11,217.175.160.12
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (file missing)
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (file missing)
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

--
End of file - 7605 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-02-21 1484056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2009-10-29 4150160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
AVG Security Toolbar BHO - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-13 279664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll [2010-02-13 812528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2009-11-03 556432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-02-21 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2010-02-13 279664]
{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [2009-11-25 1230080]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-02-21 2033432]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2010-02-13 39408]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-07-13 1173504]
"eMuleAutoStart"=C:\Program Files\eMule\emule.exe [2009-02-22 5668864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2009-10-29 4150160]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppInfo]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Base]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BFE]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Boot file system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\bowser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Browser]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\dfsc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dhcp]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DnsCache]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Dot3Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Eaphost]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EFS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\EventLog]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\File system]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\IKEEXT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\KeyIso]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanServer]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LanmanWorkstation]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\LmHosts]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Messenger]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSDrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MPSSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb10]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mrxsmb20]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NativeWifiP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NDIS Wrapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ndiscap]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ndisuio]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBIOSGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetBT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetDDEGroup]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Netlogon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetMan]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\netprofm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Network]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetworkProvider]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NlaSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Nsi]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nsiproxy.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NTDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PCI Configuration]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PlugPlay]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP Filter]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PNP_TDI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PolicyAgent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Power]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Primary disk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ProfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdbss]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpencdd.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcEptMapper]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\RpcSs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sacsvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCardSvr]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SCSI Class]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sermouse.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Streams Drivers]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SWPRV]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\System Bus Extender]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TabletInputService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TBS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Tcpip]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDI]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TrustedInstaller]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VaultSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\VDS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vga.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vgasave.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vmms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgr.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\volmgrx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinDefend]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wlansvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{36FC9E60-C465-11CF-8056-444553540000}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E965-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E967-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E969-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E972-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E973-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E974-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E975-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E977-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E980-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{50DD5230-BA8A-11D1-BF5D-0000F805F530}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a5daa49-76c7-11de-8955-806e6f6e6963}]
shell\AutoRun\command - F:\setup.exe


======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2010-02-21 20:14:27 ----D---- C:\rsit
2010-02-21 20:14:27 ----D---- C:\Program Files\trend micro
2010-02-21 16:36:32 ----D---- C:\Users\Administrateur\AppData\Roaming\AVG8
2010-02-21 15:02:56 ----HD---- C:\$AVG
2010-02-21 15:02:48 ----A---- C:\Windows\system32\avgrsstx.dll
2010-02-21 15:02:40 ----D---- C:\ProgramData\AVG Security Toolbar
2010-02-21 15:01:12 ----D---- C:\Program Files\AVG
2010-02-21 15:01:09 ----D---- C:\ProgramData\avg9
2010-02-21 08:00:44 ----D---- C:\ProgramData\Avira
2010-02-21 05:12:28 ----D---- C:\Poker
2010-02-21 04:18:35 ----N---- C:\Windows\system32\MpSigStub.exe
2010-02-21 04:16:31 ----D---- C:\Users\Administrateur\AppData\Roaming\Yahoo!
2010-02-21 03:11:15 ----D---- C:\Program Files\Microsoft Synchronization Services
2010-02-21 03:11:13 ----D---- C:\Program Files\Common Files\DESIGNER
2010-02-21 03:10:48 ----D---- C:\Windows\PCHEALTH
2010-02-21 03:10:48 ----D---- C:\Program Files\Microsoft.NET
2010-02-21 03:10:48 ----D---- C:\Program Files\Microsoft Sync Framework
2010-02-21 03:10:48 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2010-02-21 03:10:04 ----D---- C:\Program Files\Microsoft Visual Studio 8
2010-02-21 03:09:13 ----D---- C:\Program Files\Microsoft Analysis Services
2010-02-21 03:08:40 ----D---- C:\ProgramData\Microsoft Help
2010-02-21 03:08:26 ----RHD---- C:\MSOCache
2010-02-21 02:16:03 ----D---- C:\Users\Administrateur\AppData\Roaming\FTWeak
2010-02-21 02:15:55 ----D---- C:\ProgramData\FTWeak
2010-02-21 01:55:24 ----D---- C:\ProgramData\Sun
2010-02-21 01:55:24 ----D---- C:\Program Files\Common Files\Java
2010-02-21 01:55:11 ----A---- C:\Windows\system32\javaws.exe
2010-02-21 01:55:11 ----A---- C:\Windows\system32\javaw.exe
2010-02-21 01:55:11 ----A---- C:\Windows\system32\java.exe
2010-02-21 01:55:05 ----D---- C:\Program Files\Java
2010-02-21 01:52:04 ----A---- C:\Windows\system32\deploytk.dll
2010-02-21 01:45:46 ----D---- C:\Program Files\PS3 Media Server
2010-02-21 01:36:54 ----D---- C:\Users\Administrateur\AppData\Roaming\Download Manager
2010-02-21 00:06:30 ----SHD---- C:\Windows\BitLockerDiscoveryVolumeContents
2010-02-21 00:06:30 ----D---- C:\Windows\RemotePackages
2010-02-20 14:20:20 ----D---- C:\Users\Administrateur\AppData\Roaming\vlc
2010-02-20 05:25:15 ----D---- C:\Program Files\VideoLAN
2010-02-19 21:34:12 ----D---- C:\Program Files\eMule
2010-02-19 16:44:29 ----D---- C:\Users\Administrateur\AppData\Roaming\WinRAR
2010-02-19 16:10:45 ----D---- C:\Users\Administrateur\AppData\Roaming\Google
2010-02-19 16:07:06 ----D---- C:\Users\Administrateur\AppData\Roaming\Macromedia
2010-02-19 16:06:59 ----D---- C:\Users\Administrateur\AppData\Roaming\Adobe
2010-02-19 16:04:25 ----D---- C:\Users\Administrateur\AppData\Roaming\Identities
2010-02-19 16:04:14 ----SD---- C:\Users\Administrateur\AppData\Roaming\Microsoft
2010-02-19 16:04:14 ----D---- C:\Users\Administrateur\AppData\Roaming\Media Center Programs
2010-02-19 12:16:53 ----D---- C:\Program Files\SystemRequirementsLab
2010-02-18 21:51:31 ----D---- C:\Program Files\CCleaner
2010-02-18 20:05:14 ----A---- C:\Windows\system32\uxtheme.dll.backup
2010-02-18 20:05:12 ----A---- C:\Windows\system32\themeui.dll.backup
2010-02-18 20:05:10 ----A---- C:\Windows\system32\themeservice.dll.backup
2010-02-18 20:04:05 ----A---- C:\Windows\system32\termsrv.dll.backup
2010-02-18 20:03:09 ----D---- C:\Windows\pss
2010-02-18 20:00:44 ----D---- C:\Windows\My 7 Add-On
2010-02-18 20:00:44 ----A---- C:\Windows\Uninstal.exe
2010-02-16 10:18:43 ----D---- C:\ProgramData\NVIDIA
2010-02-16 10:18:22 ----D---- C:\Program Files\NVIDIA Corporation
2010-02-16 03:00:48 ----D---- C:\Program Files\MSXML 4.0
2010-02-16 00:17:07 ----D---- C:\Program Files\Common Files\Steam
2010-02-15 23:56:00 ----D---- C:\Program Files\Valve
2010-02-15 22:01:06 ----A---- C:\Windows\system32\wrap_oal.dll
2010-02-15 22:01:06 ----A---- C:\Windows\system32\OpenAL32.dll
2010-02-15 22:01:04 ----N---- C:\Windows\system32\Sens_oal.dll
2010-02-15 22:00:47 ----D---- C:\Program Files\Common Files\Creative Labs Shared
2010-02-15 22:00:33 ----D---- C:\Program Files\Creative
2010-02-15 21:59:43 ----D---- C:\ProgramData\Creative
2010-02-15 21:59:35 ----A---- C:\Windows\system32\CmdRtr.DLL
2010-02-15 21:59:35 ----A---- C:\Windows\system32\APOMngr.DLL
2010-02-15 21:59:31 ----D---- C:\Windows\system32\DATA
2010-02-15 20:45:28 ----AT---- C:\Windows\system32\SIntfNT.dll
2010-02-15 20:45:28 ----AT---- C:\Windows\system32\SIntf32.dll
2010-02-15 20:45:28 ----AT---- C:\Windows\system32\SIntf16.dll
2010-02-15 20:11:50 ----A---- C:\Windows\DIIUnin.exe
2010-02-15 20:02:52 ----D---- C:\Program Files\Diablo II
2010-02-15 13:44:23 ----D---- C:\ProgramData\Canneverbe Limited
2010-02-15 13:40:16 ----D---- C:\Program Files\CDBurnerXP
2010-02-15 13:34:15 ----D---- C:\Program Files\Nero
2010-02-15 13:34:08 ----D---- C:\ProgramData\Nero
2010-02-15 13:34:08 ----D---- C:\Program Files\Common Files\Nero
2010-02-15 11:45:48 ----A---- C:\Windows\system32\MRT.exe
2010-02-14 04:16:37 ----D---- C:\Program Files\DATABACK DriveUtility
2010-02-14 04:04:59 ----AD---- C:\ProgramData\TEMP
2010-02-14 04:01:34 ----A---- C:\Windows\system32\msv1_0.dll
2010-02-14 04:00:33 ----A---- C:\Windows\system32\tzres.dll
2010-02-14 03:50:35 ----D---- C:\Program Files\Drive Rescue
2010-02-14 03:43:59 ----A---- C:\Windows\system32\EuEpmGdi.dll
2010-02-14 03:43:58 ----A---- C:\Windows\system32\setupempdrv03.exe
2010-02-14 03:43:58 ----A---- C:\Windows\system32\BootMan.exe
2010-02-14 03:43:49 ----D---- C:\Program Files\EASEUS
2010-02-14 03:37:06 ----D---- C:\Program Files\Flash File Recovery
2010-02-14 01:15:44 ----D---- C:\Program Files\AbiWord
2010-02-14 01:09:22 ----D---- C:\Program Files\Microsoft Office
2010-02-14 01:09:17 ----D---- C:\Program Files\MSECache
2010-02-13 22:09:03 ----D---- C:\Program Files\Recuva
2010-02-13 21:49:37 ----D---- C:\OEMSettings
2010-02-13 13:31:58 ----D---- C:\ProgramData\Google
2010-02-13 13:31:10 ----D---- C:\ProgramData\Google Updater
2010-02-13 12:16:39 ----D---- C:\Program Files\WinRAR
2010-02-13 04:33:15 ----A---- C:\Windows\system32\wmp.dll
2010-02-13 04:33:14 ----A---- C:\Windows\system32\winresume.exe
2010-02-13 04:33:14 ----A---- C:\Windows\system32\winload.exe
2010-02-13 04:33:14 ----A---- C:\Windows\system32\CertEnroll.dll
2010-02-13 04:33:13 ----A---- C:\Windows\system32\wmploc.DLL
2010-02-13 04:12:19 ----A---- C:\Windows\system32\winlogon.exe
2010-02-13 04:12:19 ----A---- C:\Windows\explorer.exe
2010-02-13 04:12:13 ----A---- C:\Windows\system32\msasn1.dll
2010-02-13 04:12:04 ----A---- C:\Windows\system32\t2embed.dll
2010-02-13 04:12:04 ----A---- C:\Windows\system32\fontsub.dll
2010-02-13 04:12:03 ----A---- C:\Windows\system32\tsbyuv.dll
2010-02-13 04:12:03 ----A---- C:\Windows\system32\quartz.dll
2010-02-13 04:12:03 ----A---- C:\Windows\system32\msyuv.dll
2010-02-13 04:12:03 ----A---- C:\Windows\system32\msvidc32.dll
2010-02-13 04:12:03 ----A---- C:\Windows\system32\msrle32.dll
2010-02-13 04:12:03 ----A---- C:\Windows\system32\mciavi32.dll
2010-02-13 04:12:03 ----A---- C:\Windows\system32\iyuv_32.dll
2010-02-13 04:12:03 ----A---- C:\Windows\system32\avifil32.dll
2010-02-13 04:12:02 ----A---- C:\Windows\system32\mshtml.dll
2010-02-13 04:12:01 ----A---- C:\Windows\system32\ieframe.dll
2010-02-13 04:12:00 ----A---- C:\Windows\system32\wininet.dll
2010-02-13 04:12:00 ----A---- C:\Windows\system32\urlmon.dll
2010-02-13 04:12:00 ----A---- C:\Windows\system32\msfeedsbs.dll
2010-02-13 04:12:00 ----A---- C:\Windows\system32\iedkcs32.dll
2010-02-13 03:36:36 ----D---- C:\ProgramData\Adobe
2010-02-13 03:36:34 ----D---- C:\Program Files\Common Files\Adobe
2010-02-13 03:36:34 ----D---- C:\Program Files\Adobe
2010-02-13 03:28:18 ----D---- C:\Program Files\Restorer Ultimate
2010-02-13 02:39:20 ----D---- C:\Windows\system32\Macromed
2010-02-13 02:21:46 ----D---- C:\Program Files\PokerStars
2010-02-13 02:05:32 ----A---- C:\Windows\system32\WG511v2_OEM.tmp
2010-02-13 02:05:32 ----A---- C:\Windows\system32\MultiLanguage.tmp
2010-02-13 01:23:30 ----D---- C:\Program Files\Common Files\InstallShield
2010-02-13 01:21:53 ----D---- C:\Program Files\Google
2010-02-13 01:21:21 ----D---- C:\ProgramData\Alwil Software
2010-02-13 01:14:01 ----D---- C:\Program Files\PlayReady
2010-02-13 01:09:35 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-02-13 01:09:35 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-02-13 01:09:35 ----A---- C:\Windows\system32\halmacpi.dll
2010-02-13 01:09:35 ----A---- C:\Windows\system32\halacpi.dll
2010-02-13 01:09:35 ----A---- C:\Windows\system32\hal.dll
2010-02-13 01:09:08 ----A---- C:\Windows\system32\tquery.dll
2010-02-13 01:09:08 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2010-02-13 01:09:08 ----A---- C:\Windows\system32\SearchFilterHost.exe
2010-02-13 01:09:08 ----A---- C:\Windows\system32\mssvp.dll
2010-02-13 01:09:08 ----A---- C:\Windows\system32\mssphtb.dll
2010-02-13 01:09:08 ----A---- C:\Windows\system32\mssph.dll
2010-02-13 01:09:08 ----A---- C:\Windows\system32\msscntrs.dll
2010-02-13 01:09:07 ----A---- C:\Windows\system32\SearchIndexer.exe
2010-02-13 01:09:07 ----A---- C:\Windows\system32\mssrch.dll
2010-02-13 01:08:58 ----A---- C:\Windows\system32\PresentationHostProxy.dll
2010-02-13 01:08:58 ----A---- C:\Windows\system32\PresentationHost.exe
2010-02-13 01:08:58 ----A---- C:\Windows\system32\netfxperf.dll
2010-02-13 01:08:58 ----A---- C:\Windows\system32\mscoree.dll
2010-02-13 01:08:58 ----A---- C:\Windows\system32\dfshim.dll
2010-02-13 01:08:04 ----A---- C:\Windows\system32\atmfd.dll
2010-02-13 01:07:56 ----A---- C:\Windows\system32\uxlibres.dll
2010-02-13 01:07:56 ----A---- C:\Windows\system32\spwizres.dll
2010-02-13 01:07:56 ----A---- C:\Windows\system32\spwizimg.dll
2010-02-13 01:07:55 ----A---- C:\Windows\system32\uxlib.dll
2010-02-13 01:07:55 ----A---- C:\Windows\system32\spwizeng.dll
2010-02-13 01:07:50 ----A---- C:\Windows\system32\notepad.exe
2010-02-13 01:07:50 ----A---- C:\Windows\notepad.exe
2010-02-13 01:06:34 ----D---- C:\Program Files\Microsoft Silverlight
2010-02-13 00:13:41 ----HD---- C:\Program Files\InstallShield Installation Information
2010-02-13 00:13:16 ----D---- C:\Program Files\NETGEAR
2010-02-13 00:12:55 ----SHD---- C:\Windows\Installer
2010-02-13 00:12:54 ----D---- C:\Windows\Downloaded Installations
2010-02-13 00:08:55 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-02-13 00:05:44 ----SHD---- C:\Recovery
2010-02-13 00:05:44 ----SHD---- C:\ProgramData\Modèles
2010-02-13 00:05:44 ----SHD---- C:\ProgramData\Menu Démarrer
2010-02-13 00:05:44 ----SHD---- C:\ProgramData\Favoris
2010-02-13 00:05:44 ----SHD---- C:\ProgramData\Bureau
2010-02-13 00:05:44 ----SHD---- C:\Program Files\Fichiers communs

======List of files/folders modified in the last 1 months======

2010-02-21 20:14:43 ----D---- C:\Windows\Prefetch
2010-02-21 20:14:29 ----D---- C:\Windows\Temp
2010-02-21 20:14:27 ----RD---- C:\Program Files
2010-02-21 19:00:21 ----SHD---- C:\System Volume Information
2010-02-21 18:10:31 ----D---- C:\Windows\Tasks
2010-02-21 16:55:01 ----D---- C:\Windows\system32\config
2010-02-21 16:48:41 ----D---- C:\Windows\System32
2010-02-21 16:48:41 ----D---- C:\Windows\inf
2010-02-21 15:02:48 ----D---- C:\Windows\system32\drivers
2010-02-21 15:02:40 ----HD---- C:\ProgramData
2010-02-21 15:01:14 ----D---- C:\Windows\system32\DriverStore
2010-02-21 15:01:14 ----D---- C:\Windows\system32\catroot
2010-02-21 15:00:28 ----D---- C:\Windows
2010-02-21 14:55:08 ----D---- C:\Windows\winsxs
2010-02-21 14:53:27 ----SD---- C:\ProgramData\Microsoft
2010-02-21 08:10:51 ----D---- C:\Windows\Microsoft.NET
2010-02-21 08:10:50 ----RSD---- C:\Windows\assembly
2010-02-21 03:21:10 ----D---- C:\Program Files\Common Files\microsoft shared
2010-02-21 03:12:55 ----D---- C:\Windows\system32\Tasks
2010-02-21 03:11:52 ----RSD---- C:\Windows\Fonts
2010-02-21 03:11:37 ----D---- C:\Program Files\MSBuild
2010-02-21 03:11:22 ----D---- C:\Windows\system32\wbem
2010-02-21 03:11:15 ----D---- C:\Windows\ShellNew
2010-02-21 03:11:13 ----D---- C:\Program Files\Common Files
2010-02-21 03:09:39 ----A---- C:\Windows\win.ini
2010-02-21 03:09:38 ----D---- C:\Program Files\Common Files\System
2010-02-21 03:00:51 ----D---- C:\Windows\rescache
2010-02-21 02:25:20 ----D---- C:\Program Files\Internet Explorer
2010-02-21 01:36:53 ----D---- C:\Windows\Downloaded Program Files
2010-02-21 01:01:33 ----D---- C:\Windows\system32\oobe
2010-02-21 00:23:00 ----D---- C:\Windows\system32\catroot2
2010-02-21 00:15:23 ----D---- C:\Windows\system32\NDF
2010-02-21 00:06:30 ----D---- C:\Windows\system32\fr-FR
2010-02-21 00:06:24 ----D---- C:\Windows\system32\restore
2010-02-20 23:15:04 ----D---- C:\Windows\fr-FR
2010-02-20 22:49:29 ----D---- C:\Windows\system32\LogFiles
2010-02-19 16:04:23 ----SHD---- C:\$Recycle.Bin
2010-02-19 16:04:14 ----RD---- C:\Users
2010-02-18 22:00:54 ----D---- C:\Windows\debug
2010-02-18 20:05:14 ----A---- C:\Windows\system32\uxtheme.dll
2010-02-18 20:05:12 ----A---- C:\Windows\system32\themeui.dll
2010-02-18 20:05:10 ----A---- C:\Windows\system32\themeservice.dll
2010-02-18 20:04:05 ----A---- C:\Windows\system32\termsrv.dll
2010-02-16 10:18:39 ----D---- C:\Windows\Help
2010-02-15 15:07:33 ----HD---- C:\Windows\system32\GroupPolicy
2010-02-14 04:40:21 ----D---- C:\Windows\system32\wdi
2010-02-14 04:37:58 ----D---- C:\Windows\system32\Boot
2010-02-14 04:37:58 ----D---- C:\Windows\ehome
2010-02-14 04:37:58 ----D---- C:\Program Files\Windows Media Player
2010-02-13 02:15:09 ----SHD---- C:\Boot
2010-02-13 02:13:48 ----D---- C:\Windows\AppPatch
2010-02-13 01:24:50 ----D---- C:\Windows\Logs
2010-02-13 01:10:41 ----D---- C:\Windows\SoftwareDistribution
2010-02-13 00:08:50 ----D---- C:\Windows\system32\CodeIntegrity
2010-02-13 00:05:47 ----D---- C:\Windows\Panther
2010-02-13 00:05:44 ----D---- C:\Program Files\Windows NT

Edited by rigel, 21 February 2010 - 08:17 PM.
Moving logs to a more appro forum


BC AdBot (Login to Remove)

 


#2 germany davy

germany davy
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:56 PM

Posted 22 February 2010 - 02:04 PM

my comp is slowing, i cant run guard from avira antivir personal and i cannot activate the safe mode in internet explorer....




DDS (Ver_09-12-01.01) - NTFSx86
Run by Administrateur at 5:57:25,59 on 22/02/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Édition Intégrale 6.1.7600.0.1252.33.1036.18.3071.2182 [GMT -4:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\eMule\emule.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Administrateur\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [eMuleAutoStart] c:\program files\emule\emule.exe -AutoStart
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15111/CTPID.cab
TCP: {3489645D-0B16-40EE-A68F-46447D04D258} = 217.175.160.11,217.175.160.12
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL

============= SERVICES / DRIVERS ===============

R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-2-21 108289]
R3 RTL8167;Pilote Realtek 8167 NT;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
R3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Win7 Driver;c:\windows\system32\drivers\wg111v3.sys [2010-2-13 376832]
S1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\system32\drivers\RtlProt.sys [2007-4-23 31016]
S2 AntiVirScheduler;Planificateur Avira AntiVir Personal - Free Antivirus;"c:\program files\avira\antivir personaledition classic\sched.exe" --> c:\program files\avira\antivir personaledition classic\sched.exe [?]
S2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard;"c:\program files\avira\antivir personaledition classic\avguard.exe" --> c:\program files\avira\antivir personaledition classic\avguard.exe [?]
S2 gupdate;Service Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-13 133104]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-2-15 79360]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-2-14 14216]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-2-14 8456]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2009-10-29 30603640]
S4 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2009-9-26 4639136]

=============== Created Last 30 ================

2010-02-22 01:34:37 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-02-22 01:27:44 0 d-----w- c:\program files\Avira
2010-02-22 00:14:27 0 d-----w- c:\program files\trend micro
2010-02-21 20:36:32 0 d-----w- c:\users\admini~1\appdata\roaming\AVG8
2010-02-21 19:02:56 0 d--h--w- C:\$AVG
2010-02-21 19:02:40 0 d-----w- c:\programdata\AVG Security Toolbar
2010-02-21 19:01:12 0 d-----w- c:\program files\AVG
2010-02-21 12:00:44 0 d-----w- c:\programdata\Avira
2010-02-21 09:12:28 0 d-----w- C:\Poker
2010-02-21 08:18:35 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-02-21 07:11:15 0 d-----w- c:\program files\Microsoft Synchronization Services
2010-02-21 07:10:48 0 d-----w- c:\windows\PCHEALTH
2010-02-21 07:10:48 0 d-----w- c:\program files\Microsoft SQL Server Compact Edition
2010-02-21 07:10:04 0 d-----w- c:\program files\Microsoft Visual Studio 8
2010-02-21 07:09:13 0 d-----w- c:\program files\Microsoft Analysis Services
2010-02-21 07:08:40 0 d-----w- c:\programdata\Microsoft Help
2010-02-21 06:16:03 0 d-----w- c:\users\admini~1\appdata\roaming\FTWeak
2010-02-21 06:15:55 0 d-----w- c:\programdata\FTWeak
2010-02-21 05:55:24 0 d-----w- c:\programdata\Sun
2010-02-21 05:52:04 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-21 05:45:46 0 d-----w- c:\program files\PS3 Media Server
2010-02-21 04:06:30 0 d-sh--w- c:\windows\BitLockerDiscoveryVolumeContents
2010-02-21 04:06:30 0 d-----w- c:\windows\RemotePackages
2010-02-21 04:06:24 51867 ----a-w- c:\windows\Ultimate.xml
2010-02-21 03:29:41 20 --sh--r- C:\winx.ld
2010-02-21 03:29:40 237142 --sh--r- C:\OQFMT
2010-02-21 03:21:22 2562 ----a-w- c:\windows\diagwrn.xml
2010-02-21 03:21:22 1908 ----a-w- c:\windows\diagerr.xml
2010-02-20 09:25:15 0 d-----w- c:\program files\VideoLAN
2010-02-20 01:34:12 0 d-----w- c:\program files\eMule
2010-02-19 16:16:53 0 d-----w- c:\program files\SystemRequirementsLab
2010-02-19 01:51:31 0 d-----w- c:\program files\CCleaner
2010-02-19 00:05:14 249856 ----a-w- c:\windows\system32\uxtheme.dll.backup
2010-02-19 00:05:12 2755072 ----a-w- c:\windows\system32\themeui.dll.backup
2010-02-19 00:05:10 37376 ----a-w- c:\windows\system32\themeservice.dll.backup
2010-02-19 00:04:05 543232 ----a-w- c:\windows\system32\termsrv.dll.backup
2010-02-19 00:03:09 0 d-----w- c:\windows\pss
2010-02-19 00:01:57 1285712 ----a-w- c:\windows\system32\drivers\tcpip.sys.backup
2010-02-19 00:00:44 95110 ----a-w- c:\windows\Uninstal.exe
2010-02-19 00:00:44 0 d-----w- c:\windows\My 7 Add-On
2010-02-16 14:18:43 0 d-----w- c:\programdata\NVIDIA
2010-02-16 14:18:22 0 d-----w- c:\program files\NVIDIA Corporation
2010-02-16 07:00:48 0 d-----w- c:\program files\MSXML 4.0
2010-02-16 04:17:07 0 d-----w- c:\program files\common files\Steam
2010-02-16 03:56:00 0 d-----w- c:\program files\Valve
2010-02-16 02:01:39 7062 ----a-w- c:\windows\system32\audiopid.vxd
2010-02-16 02:01:06 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-02-16 02:01:06 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-02-16 02:01:04 2873820 ------w- c:\windows\system32\Sens_oal.dll
2010-02-16 02:00:47 0 d-----w- c:\program files\common files\Creative Labs Shared
2010-02-16 02:00:33 0 d-----w- c:\program files\Creative
2010-02-16 01:59:43 0 d-----w- c:\programdata\Creative
2010-02-16 01:59:35 87 ---ha-r- c:\windows\ctfile.rfc
2010-02-16 01:59:35 73728 ----a-w- c:\windows\system32\CmdRtr.DLL
2010-02-16 01:59:35 166912 ----a-w- c:\windows\system32\APOMngr.DLL
2010-02-16 01:59:31 0 d-----w- c:\windows\system32\DATA
2010-02-16 00:45:28 21840 ----atw- c:\windows\system32\SIntfNT.dll
2010-02-16 00:45:28 17212 ----atw- c:\windows\system32\SIntf32.dll
2010-02-16 00:45:28 12067 ----atw- c:\windows\system32\SIntf16.dll
2010-02-16 00:11:53 36443 ----a-w- c:\windows\DIIUnin.dat
2010-02-16 00:11:50 2829 ----a-w- c:\windows\DIIUnin.pif
2010-02-16 00:11:50 102400 ----a-w- c:\windows\DIIUnin.exe
2010-02-16 00:02:52 0 d-----w- c:\program files\Diablo II
2010-02-15 17:44:23 0 d-----w- c:\programdata\Canneverbe Limited
2010-02-15 17:40:21 7168 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2010-02-15 17:34:15 0 d-----w- c:\program files\Nero
2010-02-15 17:34:08 0 d-----w- c:\programdata\Nero
2010-02-14 08:16:37 0 d-----w- c:\program files\DATABACK DriveUtility
2010-02-14 08:04:59 0 d---a-w- c:\programdata\TEMP
2010-02-14 08:01:34 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-02-14 08:00:33 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-14 07:50:35 0 d-----w- c:\program files\Drive Rescue
2010-02-14 07:43:59 14848 ----a-w- c:\windows\system32\EuEpmGdi.dll
2010-02-14 07:43:58 86408 ----a-w- c:\windows\system32\setupempdrv03.exe
2010-02-14 07:43:58 8456 ----a-w- c:\windows\system32\EuGdiDrv.sys
2010-02-14 07:43:58 1692288 ----a-w- c:\windows\system32\BootMan.exe
2010-02-14 07:43:58 14216 ----a-w- c:\windows\system32\epmntdrv.sys
2010-02-14 07:43:49 0 d-----w- c:\program files\EASEUS
2010-02-14 07:37:06 0 d-----w- c:\program files\Flash File Recovery
2010-02-14 05:15:44 0 d-----w- c:\program files\AbiWord
2010-02-14 05:09:17 0 d-----w- c:\program files\MSECache
2010-02-14 01:49:37 0 d-----w- C:\OEMSettings
2010-02-14 01:48:59 376832 ----a-w- c:\windows\system32\drivers\wg111v3.sys
2010-02-13 17:31:58 0 d-----w- c:\programdata\Google
2010-02-13 17:31:10 0 d-----w- c:\programdata\Google Updater
2010-02-13 08:33:14 728648 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-02-13 08:33:14 507568 ----a-w- c:\windows\system32\winload.exe
2010-02-13 08:33:14 442920 ----a-w- c:\windows\system32\winresume.exe
2010-02-13 08:33:14 1320960 ----a-w- c:\windows\system32\CertEnroll.dll
2010-02-13 08:33:13 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-02-13 08:11:53 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-13 08:11:53 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-13 07:36:36 0 d-----w- c:\programdata\Adobe
2010-02-13 07:28:18 0 d-----w- c:\program files\Restorer Ultimate
2010-02-13 06:21:46 0 d-----w- c:\program files\PokerStars
2010-02-13 06:05:32 19 ----a-w- c:\windows\system32\WG511v2_OEM.tmp
2010-02-13 06:05:32 10870 ----a-w- c:\windows\system32\MultiLanguage.tmp
2010-02-13 05:24:36 6200 ----a-w- c:\windows\system32\int13ext.vxd
2010-02-13 05:21:21 0 d-----w- c:\programdata\Alwil Software
2010-02-13 05:14:01 0 d-----w- c:\program files\PlayReady
2010-02-13 05:08:58 76648 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-02-13 05:08:58 404320 ----a-w- c:\windows\system32\PresentationHost.exe
2010-02-13 05:08:58 291152 ----a-w- c:\windows\system32\mscoree.dll
2010-02-13 05:08:58 14160 ----a-w- c:\windows\system32\netfxperf.dll
2010-02-13 05:08:58 1083720 ----a-w- c:\windows\system32\dfshim.dll
2010-02-13 05:08:04 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-02-13 05:07:56 8338432 ----a-w- c:\windows\system32\spwizimg.dll
2010-02-13 05:07:56 7168 ----a-w- c:\windows\system32\spwizres.dll
2010-02-13 05:07:56 2560 ----a-w- c:\windows\system32\uxlibres.dll
2010-02-13 05:07:55 351744 ----a-w- c:\windows\system32\spwizeng.dll
2010-02-13 05:07:55 118784 ----a-w- c:\windows\system32\uxlib.dll
2010-02-13 05:07:50 179712 ----a-w- c:\windows\system32\notepad.exe
2010-02-13 05:07:50 179712 ----a-w- c:\windows\notepad.exe
2010-02-13 04:13:16 0 d-----w- c:\program files\NETGEAR
2010-02-13 04:12:55 0 d-sh--w- c:\windows\Installer
2010-02-13 04:12:54 0 d-----w- c:\windows\Downloaded Installations
2010-02-13 04:08:55 1524562 ----a-w- c:\windows\system32\PerfStringBackup.INI
2010-02-13 04:08:37 0 d-----w- c:\windows\system32\wbem\Performance
2010-02-13 04:05:44 0 d-sh--we c:\programdata\Modèles
2010-02-13 04:05:44 0 d-sh--we c:\programdata\Menu Démarrer
2010-02-13 04:05:44 0 d-sh--we c:\programdata\Favoris
2010-02-13 04:05:44 0 d-sh--we c:\programdata\Bureau
2010-02-13 04:05:44 0 d-sh--we c:\program files\Fichiers communs
2010-02-13 04:05:44 0 d-sh--w- C:\Recovery

==================== Find3M ====================

2010-02-22 09:45:56 694766 ----a-w- c:\windows\system32\perfh00C.dat
2010-02-22 09:45:56 127478 ----a-w- c:\windows\system32\perfc00C.dat
2010-02-19 00:05:14 249856 ----a-w- c:\windows\system32\uxtheme.dll
2010-02-19 00:05:12 2755072 ----a-w- c:\windows\system32\themeui.dll
2010-02-19 00:05:10 37376 ----a-w- c:\windows\system32\themeservice.dll
2010-02-19 00:04:05 543232 ----a-w- c:\windows\system32\termsrv.dll
2010-02-19 00:01:58 1279544 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-13 05:09:04 37665 ----a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont
2010-01-12 02:18:00 962664 ----a-w- c:\windows\system32\nvsvc.dll
2010-01-12 02:18:00 66664 ----a-w- c:\windows\system32\nvshext.dll
2010-01-12 02:18:00 13679720 ----a-w- c:\windows\system32\nvcpl.dll
2010-01-12 02:18:00 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-01-12 02:18:00 110696 ----a-w- c:\windows\system32\nvmctray.dll
2009-12-19 09:02:55 977920 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 09:02:52 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-19 09:02:48 1328640 ----a-w- c:\windows\system32\quartz.dll
2009-12-19 09:02:46 22016 ----a-w- c:\windows\system32\msyuv.dll
2009-12-19 09:02:45 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-19 09:02:45 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-19 09:02:40 84480 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-19 09:02:39 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-19 09:02:01 91648 ----a-w- c:\windows\system32\avifil32.dll
2009-11-18 23:09:52 376832 ----a-w- c:\windows\inf\wg111v3\win7x86\WG111v3.sys
2009-11-18 23:09:52 376832 ----a-w- c:\windows\inf\wg111v3\WG111v3.sys
2009-11-18 22:47:46 446976 ----a-w- c:\windows\inf\wg111v3\win7x64\WG111v3.sys
2009-08-14 02:19:56 73728 ----a-w- c:\windows\inf\wg111v3\win7x64\SetVistaDrv64.exe
2009-07-20 23:20:04 65536 ----a-w- c:\windows\inf\wg111v3\win7x86\SetVistaDrv.exe
2009-07-20 23:20:04 65536 ----a-w- c:\windows\inf\wg111v3\SetVistaDrv.exe
2009-07-14 08:39:32 38160 ----a-w- c:\windows\inf\perflib\040c\perfd.dat
2009-07-14 08:39:32 38160 ----a-w- c:\windows\inf\perflib\040c\perfc.dat
2009-07-14 08:39:32 344522 ----a-w- c:\windows\inf\perflib\040c\perfi.dat
2009-07-14 08:39:32 344522 ----a-w- c:\windows\inf\perflib\040c\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-03 15:36:22 74752 ----a-w- c:\windows\inf\wg111v3\SetDrv64.exe
2009-06-03 15:30:26 49152 ----a-w- c:\windows\inf\wg111v3\SetDrv.exe
2008-12-12 23:13:32 512000 ----a-w- c:\windows\inf\wg111v3\win7x64\DIFxAPI.dll
2008-12-12 22:57:46 313856 ----a-w- c:\windows\inf\wg111v3\win7x86\DIFxAPI.dll
2008-12-12 22:57:46 313856 ----a-w- c:\windows\inf\wg111v3\DIFxAPI.dll
2007-04-23 18:15:48 31016 ----a-w- c:\windows\inf\wg111v3\vista64\RtlProt.sys
2007-04-23 15:50:50 25896 ----a-w- c:\windows\inf\wg111v3\vista\RtlProt.sys
2007-04-20 02:22:44 75264 ----a-w- c:\windows\inf\wg111v3\vista64\rtkbind.exe
2007-04-20 02:22:28 74752 ----a-w- c:\windows\inf\wg111v3\vista\rtkbind.exe
2006-12-15 16:30:36 98304 ----a-w- c:\windows\inf\wg111v3\UScanM.exe
2006-12-15 16:30:36 315392 ----a-w- c:\windows\inf\wg111v3\InstallDriver.exe
2006-12-15 16:30:36 212992 ----a-w- c:\windows\inf\wg111v3\CopyWHQLDriver.exe
2006-12-15 16:30:36 20480 ----a-w- c:\windows\inf\wg111v3\RTWUPath.exe
2006-12-15 16:30:36 19968 ----a-w- c:\windows\inf\wg111v3\RTWREFU.EXE
2006-03-16 13:24:24 49664 ----a-w- c:\windows\inf\wg111v3\devcon.exe
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 5:57:44,19 ===============

Attached Files


Edited by Orange Blossom, 22 February 2010 - 02:53 PM.
Merged topics. ~ OB


#3 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:11:56 PM

Posted 23 February 2010 - 08:56 PM

Hello,

How is your English?
Posted Image
m0le is a proud member of UNITE

#4 germany davy

germany davy
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:07:56 PM

Posted 25 February 2010 - 10:29 PM

imy english is pretty good i hope so and i will donate if u give a good help

Edited by germany davy, 25 February 2010 - 10:30 PM.


#5 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:11:56 PM

Posted 26 February 2010 - 07:03 PM

Nothing is showing up on the logs.


Let's see if we can fix your safe mode

We Need to Repair Safe Mode
  1. Please download Safe Boot Key Repair and save it to your desktop.
  2. Open on your desktop.
  3. Copy and paste the resultant log here in your next reply.

Now safe mode is working please run Dr Web

Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

Please download DrWeb-CureIt and save it to your desktop. DO NOT perform a scan yet.

Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with Dr.Web CureIt as follows:
  • Double-click on launch.exe to open the program and click Start. (There is no need to update if you just downloaded the most current version
  • Read the Virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.
  • The Express scan will automatically begin.
    (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
  • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
  • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All. (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
  • After the Express Scan is finished, put a check next to Complete scan to scan all local disks and removable media.
  • In the top menu, click Settings > Change settings, and uncheck "Heuristic analysis" under the "Scanning" tab, then click Apply, Ok.
  • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
  • Please be patient as this scan could take a long time to complete.
  • When the scan has finished, a message will be displayed at the bottom indicating if any viruses were found.
  • Click Select All, then choose Cure > Move incurable.
  • In the top menu, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
Thanks smile.gif
Posted Image
m0le is a proud member of UNITE

#6 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:11:56 PM

Posted 02 March 2010 - 09:10 PM

Hi,

I have not had a reply from you for 3 days. Can you please tell me if you still need help with your computer as I am unable to help other members with their problems while I have your topic still open. The time taken between posts can also change the situation with your PC making it more difficult to help you.

If you like you can PM me.

Thanks,


m0le
Posted Image
m0le is a proud member of UNITE

#7 m0le

m0le

    Can U Dig It?


  • Malware Response Team
  • 34,527 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:11:56 PM

Posted 04 March 2010 - 06:11 PM

This topic has been closed.

If you're the topic starter, and need this topic reopened, please contact me via pm with the address of the thread.

Everyone else please begin a New Topic.
Posted Image
m0le is a proud member of UNITE




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users